CVE-2021-28113
18Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.7epss 22%
exploitation probability
22%top 2% of all CVEs
observed exploitation
nono source reports it
A command injection vulnerability in the cookieDomain and relayDomain parameters of Okta Access Gateway before 2020.9.3 allows attackers (with admin access to the Okta Access Gateway UI) to execute OS commands as a privileged system account.
CVSS:3.1/AC:L/AV:N/A:L/C:H/I:H/PR:H/S:U/UI:N
Affected products
n/a · n/a